CVE-2026-13084Disclosure(watchguard / firebox_cloud)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch watchguard firebox_cloud systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially crafted IKEv2 messages. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firebox_cloud
  • firebox_m270
  • firebox_m290
  • firebox_m295

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-07-03); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
firebox_cloudfirebox_m270firebox_m290firebox_m295firebox_m370firebox_m390firebox_m395firebox_m440firebox_m4600firebox_m470

2 versions affected across 39 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-07-03: 3Mentions · 2026-07-15: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-03: 307-0307-15
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-033
Disclosure2Patch1
2026-07-151
Disclosure1
Full discourse4 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos WatchGuard ❗ CVE-2026-13368 ❗ CVE-2026-13084 ❗ CVE-2026-13050 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-watchguard-5/ https://t.co/18T6zx1S9J

    Post summary

    The post announces three WatchGuard CVE identifiers and provides links for additional information, but supplies no further details about the vulnerabilities.

    00000194
    6.7K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-13084 (CVSS 8.7) in WatchGuard Fireware OS can trigger remote DoS via IKEv2. Impacted organizations should evaluate exposure and apply fixes. https://nvd.nist.gov/vuln/detail/CVE-2026… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/NsETpFgRPv

    Post summary

    The tweet announces CVE‑2026‑13084, a high‑severity remote DoS vulnerability in WatchGuard Fireware OS via IKEv2, and urges affected organizations to evaluate exposure and apply available fixes.

    0000062
    92 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13084 A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sendin… https://www.cve.org/CVERecord?id=CVE-2026-13084 ----- Traducción: CVE-2026-13084 Una… http://infoflow.cloud`

    Post summary

    The post announces a new CVE (CVE-2026-13084) describing a null pointer dereference in WatchGuard Fireware OS that permits remote unauthenticated Denial‑of‑Service attacks, with a link to the official CVE record.

    0000041
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-13084 A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sendin… https://www.cve.org/CVERecord?id=CVE-2026-13084

    Post summary

    The text reports CVE-2026-13084, a null pointer dereference in WatchGuard Fireware OS enabling remote unauthenticated Denial‑of‑Service, with no evidence of active exploitation, exploit code, or patch information.

    00000748
    57.7K followersView on X
CPE platform detail41 entries

41 of 41 entries

PartVendorProductVersionTarget SWTarget HW
Appwatchguardfirebox_cloud---
HWwatchguardfirebox_m270---
HWwatchguardfirebox_m290---
HWwatchguardfirebox_m295---
HWwatchguardfirebox_m370---
HWwatchguardfirebox_m390---
HWwatchguardfirebox_m395---
HWwatchguardfirebox_m440---
HWwatchguardfirebox_m4600---
HWwatchguardfirebox_m470---
HWwatchguardfirebox_m4800---
HWwatchguardfirebox_m495---
HWwatchguardfirebox_m5600---
HWwatchguardfirebox_m570---
HWwatchguardfirebox_m5800---
HWwatchguardfirebox_m590---
HWwatchguardfirebox_m595---
HWwatchguardfirebox_m670---
HWwatchguardfirebox_m690---
HWwatchguardfirebox_m695---
HWwatchguardfirebox_nv5---
HWwatchguardfirebox_t115-w---
HWwatchguardfirebox_t125---
HWwatchguardfirebox_t125-w---
HWwatchguardfirebox_t145---
HWwatchguardfirebox_t145-w---
HWwatchguardfirebox_t15---
HWwatchguardfirebox_t185---
HWwatchguardfirebox_t20---
HWwatchguardfirebox_t25---
HWwatchguardfirebox_t35---
HWwatchguardfirebox_t40---
HWwatchguardfirebox_t45---
HWwatchguardfirebox_t55---
HWwatchguardfirebox_t70---
HWwatchguardfirebox_t80---
HWwatchguardfirebox_t85---
HWwatchguardfireboxv---
OSwatchguardfireware---
OSwatchguardfireware11.12.4--
OSwatchguardfireware11.12.4--

Explore more